New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Security 300-715 Questions and answers with CertsForce

Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions
Questions # 31:

An engineer is testing Cisco ISE policies in a lab environment with no support for a deployment server. In order to push supplicant profiles to the workstations for testing, firewall ports will need to be opened. From which Cisco ISE persona should this traffic be originating?

Options:

A.

monitoring


B.

policy service


C.

administration


D.

authentication


Expert Solution
Questions # 32:

Which two ports must be open between Cisco ISE and the client when you configure posture on Cisco ISE? (Choose two).

Options:

A.

TCP 8443


B.

TCP 8906


C.

TCP 443


D.

TCP 80


E.

TCP 8905


Expert Solution
Questions # 33:

Refer to the exhibit.

Question # 33

An engineer must configure Cisco ISE to be used as the TACACS+ server for any administrator that signs into the router. Users must be able to change their Telnet password through the TACACS+ server. Drag and drop the configuration steps from the left into the sequence on the right.

Question # 33


Expert Solution
Questions # 34:

A network engineer must configure a policy rule to check the endpoint. The policy must ensure disk encryption is enabled and the appropriate antivirus software version is installed. Which configuration must the engineer apply to the rule?

Options:

A.

dictionary simple condition


B.

simple posture condition


C.

dictionary compound condition


D.

compound posture condition


Expert Solution
Questions # 35:

An engineer is configuring the remote access VPN to use Cisco ISE for AAA and needs to conduct posture checks on the connecting endpoints After the endpoint connects, it receives its initial authorization result and continues onto the compliance scan What must be done for this AAA configuration to allow compliant access to the network?

Options:

A.

Configure the posture authorization so it defaults to unknown status


B.

Fix the CoA port number


C.

Ensure that authorization only mode is not enabled


D.

Enable dynamic authorization within the AAA server group


Expert Solution
Questions # 36:

What is a difference between RADIUS and TACACS+?

Options:

A.

RADIUS uses connection-oriented transport, and TACACS+ uses best-effort delivery.


B.

RADIUS offers multiprotocol support, and TACACS+ supports only IP traffic.


C.

RADIUS combines authentication and authorization functions, and TACACS+ separates them.


D.

RADIUS supports command accounting, and TACACS+ does not.


Expert Solution
Questions # 37:

An engineer is configuring 802.1X and is testing out their policy sets. After authentication, some endpoints are given an access-reject message but are still allowed onto the network. What is causing this issue to occur?

Options:

A.

The switch port is configured with authentication event server dead action authorize vlan.


B.

The authorization results for the endpoints include a dACL allowing access.


C.

The authorization results for the endpoints include the Trusted security group tag.


D.

The switch port is configured with authentication open.


Expert Solution
Questions # 38:

An administrator needs to give the same level of access to the network devices when users are logging into them using TACACS+ However, the administrator must restrict certain commands based on one of three user roles that require different commands How is this accomplished without creating too many objects using Cisco ISE?

Options:

A.

Create one shell profile and multiple command sets.


B.

Create multiple shell profiles and multiple command sets.


C.

Create one shell profile and one command set.


D.

Create multiple shell profiles and one command set


Expert Solution
Questions # 39:

What is the Microsoft security policy recommendation (or fast user switching in Cisco ISE?

Options:

A.

Disable BYOD posture agent.


B.

Enable fast user switching.


C.

Disable fast user switching.


D.

Enable Cisco Secure Client posture agent.


Expert Solution
Questions # 40:

Which profiling probe collects the user-agent string?

Options:

A.

DHCP


B.

AD


C.

HTTP


D.

NMAP


Expert Solution
Viewing page 4 out of 9 pages
Viewing questions 31-40 out of questions